Openfire 'muc-room-edit-form.jsp' HTML Injection Vulnerability
BID:32944
Info
Openfire 'muc-room-edit-form.jsp' HTML Injection Vulnerability
| Bugtraq ID: | 32944 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0496 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 08 2009 12:00AM |
| Updated: | Mar 19 2015 08:17AM |
| Credit: | Federico Muttis of Core Security Technologies |
| Vulnerable: |
Ignite Realtime Openfire 3.6.2 Ignite Realtime Openfire 3.5.2 Ignite Realtime Openfire 3.5.1 Ignite Realtime Openfire 3.5 Ignite Realtime Openfire 3.4.5 Ignite Realtime Openfire 3.4.4 Ignite Realtime Openfire 3.4.3 Ignite Realtime Openfire 3.4.2 Ignite Realtime Openfire 3.4.1 Ignite Realtime Openfire 3.4 Ignite Realtime Openfire 3.3.1 Ignite Realtime Openfire 3.3 Ignite Realtime Openfire 3.6.0a Gentoo Linux |
| Not Vulnerable: |
Ignite Realtime Openfire 3.6.3 |
Discussion
Openfire 'muc-room-edit-form.jsp' HTML Injection Vulnerability
Openfire is prone to a HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Openfire 3.6.2 is vulnerable; prior versions may also be affected.
Openfire is prone to a HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Openfire 3.6.2 is vulnerable; prior versions may also be affected.
Exploit / POC
Openfire 'muc-room-edit-form.jsp' HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Openfire 'muc-room-edit-form.jsp' HTML Injection Vulnerability
Solution:
Vendor updates are available. Contact the vendor for details.
Solution:
Vendor updates are available. Contact the vendor for details.
References
Openfire 'muc-room-edit-form.jsp' HTML Injection Vulnerability
References:
References:
- Openfire Homepage (Ignite Realtime)
- CORE-2008-1128: Openfire multiple vulnerabilities (CORE Security Technologies Advisories
) - Openfire multiple vulnerabilities (Core Security Technologies)